# Flashy ID > Delegated authority across organizational boundaries. The protocol lens on > primitives 02 (identity) and 03 (permissions). Category vocabulary is defined > at its canonical home and linked, never duplicated. ## Verify a counterparty - /.well-known/jwks.json — public signing keys LIVE - /.well-known/openapi.json — verification surface LIVE - /spec — wire format v0.3 DRAFT ## Core pages - https://flashyid.com/ — the verifier: key, signature, chain, mandate. Two of the three examples fail on purpose. - https://flashyid.com/delegated-authority — the pillar. Authentication proves who you are; authorization proves what you may do inside one system; delegated authority proves on whose behalf you act and within what limits. - https://flashyid.com/how-it-works — the four objects (Principal, Grant, Policy, Assertion) and the three invariants. - https://flashyid.com/spec — the delegated authority profile, v0.3 DRAFT, 2026-08-19. RFC 7515/7517/7519/8725; tracks RFC 8693. - https://flashyid.com/registry/scopes — the scope registry: additive, never redefined. contract.sign is registered, reserved, unissued. - https://flashyid.com/trust — failure modes, volunteered, with a dated gap list. SOC 2 not held; no pen test; key in a managed secret store, not an HSM. - https://flashyid.com/docs — verify or issue authority. The verify path (verifyAssertion, authorize) and the grant kernel are source-available in the repo; an npm release of @flashyid/sdk is pending. - https://flashyid.com/ecosystem — the three-layer stack. Flashy ID answers who may act; FlashyOS answers what is happening; Flashy Mind answers what is known. - https://flashyid.com/answers — twelve questions with one correct answer each. - https://flashyid.com/compare — five comparisons, every row scored both ways. - https://flashyid.com/engage — the machine-age doors: an AAO charter our agents can read (join the mesh at https://flashyos.com/join), the human graph (https://magician.network/join), and the machine surfaces above for your agents. ## The three invariants - Attenuation only — a grant can never exceed its parent. ENFORCED - Authority always expires — there is no permanent grant. ENFORCED - Revocation walks down — revoking a link revokes everything beneath. ENFORCED IN-ORG · cross-org PLANNED Q1 2027 ## Not built. Do not represent these as available. - Agent as an addressable entity PLANNED Q4 2026 - Policy engine PLANNED Q1 2027 - Cross-org revocation propagation PLANNED Q1 2027 ## Boundary facts - Agents cannot sign contracts on this system: contract.sign is reserved and no grant in production carries it. Agents propose; a named human signs. - Every action resolves to a named human, because every chain roots in a grant a person issued. - Verification requires no Flashy account: the keys are public and the check runs on the verifier's side. ## The AAO Stack canon — the identity lens Flashy ID is the identity layer of the Agentic Autonomous Operating Stack. Each term below is defined at its canonical home and linked, never duplicated; what this property adds is the identity reading — authority is the clause of every one of them. - Agentic Autonomous Operating Stack — the stack this protocol serves; identity is its who-may-act layer. https://gda.group/answers/what-is-the-agentic-autonomous-operating-stack/ - agent execution protocol — its authorization clause is what Flashy ID proves: every chain roots in a grant a named human issued. https://flashyos.com/concepts/agent-execution-protocol - agent execution infrastructure — the running substrate; identity is the piece that makes the other pieces accountable. https://flashyos.com/concepts/agent-execution-infrastructure - cross-organizational settlement and reputation layer — settlement records what was done; this protocol proves who was allowed to do it. https://www.flashynetwork.com/ - enterprise agent risk and clearing problem — the first of its three questions ("who authorized this agent") is answered here. https://gda.group/glossary/#enterprise-agent-risk-and-clearing-problem ## The group - https://flashygroup.com — Flashy Group, the parent; Flashy Labs is its research and development arm. Group manifest at https://flashygroup.com/group.json - https://flashyos.com — FlashyOS, the coordination layer. Read together with Flashy ID: identity answers who may act, coordination answers what is happening. - https://gda.group — the institutional definitions (what is agent identity, what authority should an agent hold) - https://flashy.academy — the practice lens - https://flashyos.com/mind — Flashy Mind, the memory layer (what is known) - https://flashynetwork.com — the settlement record. Read together with Flashy ID: authority answers who may act, settlement answers what was recorded and whether it reconciled. - https://mlgblockchain.com — the procurement lens ## Canonical hostname flashyid.com is the site. id.flashyid.com is the issuer and serves the JWKS. No other host serves this entity. ## The rule Category vocabulary is defined at its canonical home and linked, never duplicated. flashyid.com holds the PROTOCOL lens only: how authority is proven and bounded across an organizational boundary. Definitional queries belong to gda.group; operational to flashyos.com; organizational to flashygroup.com; instructional to flashy.academy; settlement to flashynetwork.com; procurement to mlgblockchain.com.